Summary: | <dev-util/rizin-0.4.1: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | ajak, sam |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B2 [glsa+] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
2022-09-07 00:02:10 UTC
CVE-2022-36039 (https://github.com/rizinorg/rizin/security/advisories/GHSA-pr85-hv85-45pg): Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to out-of-bounds write when parsing DEX files. A user opening a malicious DEX file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. A patch is available on the `dev` branch of the repository. https://github.com/rizinorg/rizin/issues/2969 https://github.com/rizinorg/rizin/commit/1524f85211445e41506f98180f8f69f7bf115406 CVE-2022-36042 (https://github.com/rizinorg/rizin/security/advisories/GHSA-pf72-jg54-8gvp): Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to an out-of-bounds write when getting data from dyld cache files. A user opening a malicious dyld cache file could be affected by this vulnerability, allowing an attacker to execute code on the user's machine. Commit number 556ca2f9eef01ec0f4a76d1fbacfcf3a87a44810 contains a patch. https://github.com/rizinorg/rizin/commit/556ca2f9eef01ec0f4a76d1fbacfcf3a87a44810 The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c1e0726a3bb3579ce4d2e555707a41906967719c commit c1e0726a3bb3579ce4d2e555707a41906967719c Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2022-09-10 15:29:16 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-09-10 15:29:33 +0000 dev-util/rizin: add 0.4.1 Bug: https://bugs.gentoo.org/868999 Signed-off-by: John Helmert III <ajak@gentoo.org> dev-util/rizin/Manifest | 2 + dev-util/rizin/rizin-0.4.1.ebuild | 94 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 96 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=afc498940ea5697bf841f7f8e052be6ec4768396 commit afc498940ea5697bf841f7f8e052be6ec4768396 Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2022-09-18 21:40:45 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-09-18 21:42:57 +0000 dev-util/rizin: drop 0.4.0-r1 Bug: https://bugs.gentoo.org/861524 Bug: https://bugs.gentoo.org/868999 Signed-off-by: John Helmert III <ajak@gentoo.org> dev-util/rizin/Manifest | 2 - dev-util/rizin/files/rizin-0.4.0-capstone.patch | 22 ------ dev-util/rizin/rizin-0.4.0-r1.ebuild | 95 ------------------------- 3 files changed, 119 deletions(-) Request filed GLSA released, all done! The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=89088d8ee19407be5e30c10d244979cbc879b19f commit 89088d8ee19407be5e30c10d244979cbc879b19f Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-09-25 13:33:58 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-09-25 13:42:17 +0000 [ GLSA 202209-06 ] Rizin: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/861524 Bug: https://bugs.gentoo.org/868999 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202209-06.xml | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) |